CompTIA · N10-009 · Intermediate
CompTIA Network+ (N10-009) practice questions
8 sample questions from our 260-question Network+ bank, one from each official domain. The answer and a full explanation sit under each one. Every question is original, written against the published exam objectives, and quality-checked before it reaches you.
Question 1 · Networking Concepts
A technician at BrightTech Inc. configures a new subnet with the IP range 192.168.50.0/26. After deployment, several hosts cannot communicate outside their subnet. What is the most likely cause of this issue?
- A.The subnet mask is too restrictive, limiting the number of usable host addresses.
- B.Hosts have static IPs that overlap with another subnet in the network.
- C.The default gateway is incorrectly set to 192.168.50.1, which is outside the subnet range.
- D.The DHCP server is assigning IPs from a different subnet range.
Show answer & explanation
Answer: A
A /26 subnet mask allows only 62 usable hosts, so if more devices are present or configured outside that range, communication issues occur. The default gateway 192.168.50.1 is valid within 192.168.50.0/26, so it is unlikely the cause. DHCP assigning from another subnet or overlapping static IPs would cause different symptoms.
Question 2 · Infrastructure
The IT manager at DataCore wants to segment traffic between finance and HR departments to minimize broadcast domains without adding additional physical switches. Which device and technology combination should be implemented?
- A.Use a network hub and separate the departments using different IP subnets.
- B.Replace all switches with Layer 3 switches to route between departments.
- C.Deploy wireless access points with different SSIDs for each department.
- D.Add VLANs on the existing switches and assign ports accordingly.
Show answer & explanation
Answer: D
Creating VLANs on existing switches logically segments traffic into separate broadcast domains without extra hardware. Layer 3 switches provide routing but are not needed just for segmentation. Hubs do not segment traffic, and different SSIDs separate wireless clients, not wired VLAN traffic.
Question 3 · Network Troubleshooting and Tools
The help desk at Orion Corp receives complaints that users on the 10.10.20.0/24 subnet cannot access websites, but users on 10.10.30.0/24 subnet can. Both subnets are connected to the same router. What is the first logical step to troubleshoot this issue?
- A.Replace the switch connecting the 10.10.20.0 subnet hosts.
- B.Disable firewall on the router for the 10.10.30.0 subnet temporarily.
- C.Verify the router’s routing table includes a route for 10.10.20.0/24.
- D.Check DNS server settings for clients on the 10.10.20.0 subnet.
Show answer & explanation
Answer: D
Since users on one subnet can browse websites but not on the other, name resolution (DNS) is a likely cause. Checking the routing table is useful if no connectivity exists at all, but here the issue is accessing websites, which often involves DNS. Replacing hardware or disabling firewalls should be later steps.
Question 4 · Network Security
A technician at Velocity Networks sets up a new wireless LAN using WPA3-Personal security. After deployment, some older client devices cannot connect to the Wi-Fi. What is the most probable reason?
- A.The SSID was hidden by default, preventing device discovery.
- B.MAC filtering is enabled, blocking older devices.
- C.WPA3 encrypts traffic using AES, which older devices do not support.
- D.Older devices do not support WPA3 and require WPA2 compatibility mode.
Show answer & explanation
Answer: D
WPA3 is a newer Wi-Fi security protocol that many older devices lack support for, necessitating WPA2 compatibility for backward compatibility. Hiding SSID or MAC filtering would block devices regardless of encryption. AES encryption is supported by WPA2 as well.
Question 5 · Network Operations
A new VoIP system at CloudNet requires low latency and jitter on the network. The network engineer notices inconsistent call quality during business hours. What network feature should be configured to prioritize VoIP traffic?
- A.Enable port mirroring to monitor VoIP traffic in real time.
- B.Implement Quality of Service (QoS) policies on routers and switches.
- C.Increase the MTU size to allow bigger packets to pass.
- D.Disable all wireless access points to reduce interference.
Show answer & explanation
Answer: B
QoS allows prioritizing latency-sensitive traffic like VoIP to ensure consistent call quality. Increasing MTU does not address latency or jitter, disabling access points is unrelated unless wireless VoIP is used, and port mirroring is for monitoring, not traffic prioritization.
Question 6 · Networking Concepts
A company is transitioning to IPv6 internally. The network admin assigns an IPv6 address to a workstation and tries to ping the default gateway’s IPv6 address but receives no response. Which step is most likely missing from the configuration?
- A.Configuring the workstation’s subnet mask correctly.
- B.Setting up DHCPv6 server for address assignment.
- C.Disabling IPv4 on the workstation to avoid conflicts.
- D.Enabling IPv6 routing on the router.
Show answer & explanation
Answer: D
If the router does not have IPv6 routing enabled, it won’t forward IPv6 packets or respond to pings. IPv6 uses prefixes rather than subnet masks, and disabling IPv4 is not necessary. DHCPv6 is optional because IPv6 supports stateless address autoconfiguration.
Question 7 · Infrastructure
At Netwise Solutions, a network engineer notices that the latency spikes whenever multiple users access a server simultaneously. The server NIC is 1 Gbps, but the switch port is limited to 100 Mbps. What should the engineer do to best resolve the bottleneck?
- A.Upgrade the switch port to a 1 Gbps port to match the server NIC.
- B.Increase the server’s RAM to handle more simultaneous requests.
- C.Configure QoS on the switch to prioritize server traffic.
- D.Add another 100 Mbps NIC to the server to balance the load.
Show answer & explanation
Answer: A
The bottleneck is the slower 100 Mbps switch port causing latency despite the faster NIC. Matching the switch port speed to the server NIC capacity eliminates this limitation. Adding another NIC or increasing RAM won’t improve network throughput directly, and QoS prioritization doesn’t increase bandwidth.
Question 8 · Network Troubleshooting and Tools
A network analyst at SkyLogix notices that ping packets to a server in a remote branch consistently time out, but traceroute shows the path reaching the server's subnet. What is the most probable network device causing the ping to fail?
- A.Firewall blocking ICMP echo requests on the server’s subnet.
- B.Router interface missing a default route to the server.
- C.DNS server misconfigured causing name resolution failure.
- D.Switch port configured as a trunk link between sites.
Show answer & explanation
Answer: A
Firewalls commonly block ICMP echo requests which are used by ping, causing timeouts. Traceroute reaching the subnet shows routing is intact, so missing default routes are unlikely. Switch trunks and DNS misconfiguration would not cause ping to fail if IP connectivity exists.
252+ more questions, free
Full-length, in timed or practice mode, and weighted to the official blueprint. Per-domain scoring shows you exactly where you stand.
Start the full practice exam →